CVE-2005-1031
N/A
N/A
Summary
RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.runcms.org/public/modules/news/
- http://secunia.com/advisories/14869
- http://marc.info/?l=bugtraq&m=111280711228450&w=2
- http://www.securityfocus.com/bid/13027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20001
References
- http://www.runcms.org/public/modules/news/
- http://secunia.com/advisories/14869
- http://marc.info/?l=bugtraq&m=111280711228450&w=2
- http://www.securityfocus.com/bid/13027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20001
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.